Containers, Cloud & DevOps

Containers, orchestration, deployment, networking, storage, security, autoscaling and the infrastructure patterns behind modern cloud-native applications.

Containers are one of the clearest examples of how operating-system concepts, software architecture and infrastructure engineering converge.

They make applications easier to package and reproduce, but running a container is only the beginning. Once applications consist of many containers distributed across multiple machines, new questions appear around scheduling, networking, persistence, security, scaling and failure recovery.

What exactly is isolated inside a container? Why is a container lighter than a virtual machine? How should a container image be built and secured? What happens when a container fails? How can hundreds of containers be deployed, updated and scaled without managing each one manually?

This section combines two complementary perspectives: understanding containers themselves through Docker, and understanding how containerized workloads can be orchestrated at scale through Kubernetes.


Topics in This Section

Containers · OCI · Docker · Container Images · Dockerfiles · Registries · Docker Compose · Container Networking · Persistent Volumes · Container Security · Kubernetes · Pods · ReplicaSets · Deployments · Services · Ingress · Autoscaling · Self-Healing · ConfigMaps · Secrets · RBAC · Service Mesh · Stateful Workloads · Persistent Storage · Network Policies · Policy & Governance · Multicluster Deployment · Cloud-Native Applications


Docker Deep Dive

Nigel Poulton

5th Edition — Packt Publishing

Level
Foundation → Intermediate

Best for
Understanding container fundamentals, Docker architecture and the practical lifecycle of containerized applications.

Docker Deep Dive is the book I use to understand what happens before orchestration begins.

It moves from the fundamental difference between containers and virtual machines to Docker Engine internals, images, application containerization, networking, persistent storage and security.

I find this particularly useful because it connects the simple developer experience of running a container with the operating-system mechanisms and standards underneath it.

What I Use It For

  • understanding containers versus virtual machines;
  • the Open Container Initiative and container standards;
  • Docker Engine architecture;
  • containerd and runc;
  • container images and layers;
  • registries, tags and digests;
  • Dockerfiles;
  • multi-stage builds;
  • multi-architecture images;
  • Docker Compose;
  • container networking;
  • overlay networks;
  • persistent volumes;
  • container isolation and security;
  • namespaces and control groups;
  • capabilities and seccomp;
  • image vulnerability scanning.

Chapters Worth Reading

Container Foundations

Chapter 1 — Containers from 30,000 Feet
Why containers emerged, how they differ from virtual machines and where they fit in modern infrastructure.

Chapter 2 — Docker and Container-Related Standards and Projects
Docker’s place in the wider container ecosystem and the standards that allow container runtimes and images to interoperate.

Docker Architecture

Chapter 5 — The Docker Engine
The internal components behind the Docker runtime.

  • Docker Engine;
  • Open Container Initiative;
  • containerd;
  • runc;
  • container lifecycle;
  • Linux implementation.
Images & Containers

Chapter 6 — Working with Images
Container images, layers, registries, tagging, digests and multi-architecture images.

  • image layers;
  • registries;
  • tags and digests;
  • multi-architecture images;
  • Docker Scout vulnerability scanning.

Chapter 7 — Working with Containers
The practical container lifecycle and the relationship between images and running containers.

  • containers versus VMs;
  • starting and stopping containers;
  • process inspection;
  • debugging;
  • restart policies and basic self-healing.
Containerizing Applications

Chapter 8 — Containerizing an App
Moving an application into a reproducible container image.

  • Dockerfiles;
  • single-container applications;
  • multi-stage builds;
  • BuildKit;
  • Buildx;
  • multi-architecture builds;
  • container-image best practices.
Multi-Container Applications

Chapter 9 — Multi-Container Apps with Compose
Defining and running applications composed of multiple cooperating containers.

  • Compose files;
  • application services;
  • multi-container deployment;
  • application lifecycle management.
Container Orchestration

Chapter 12 — Docker Swarm
A compact introduction to Docker’s native orchestration system.

I mainly use this chapter to understand orchestration concepts in a simpler environment before moving to Kubernetes: clusters, distributed application deployment and replicated services.

Networking

Chapter 13 — Docker Networking
Container networking on a single Docker host.

  • bridge networks;
  • container connectivity;
  • port mappings;
  • external access.

Chapter 14 — Docker Overlay Networking
Networking across multiple hosts and the abstractions used to connect distributed containers.

Persistent Data

Chapter 15 — Volumes and Persistent Data
Why container filesystems should generally be treated as ephemeral and how persistent state can be separated from container lifecycle.

Container Security

Chapter 16 — Docker Security
The Linux and Docker mechanisms used to isolate and protect containers.

  • kernel namespaces;
  • control groups;
  • Linux capabilities;
  • Mandatory Access Control;
  • seccomp;
  • image vulnerability scanning;
  • image signing;
  • Docker Secrets.

My Suggested Learning Path

Understand Containers
Chapters 1–2

Understand the Runtime
Chapter 5

Images & Containers
Chapters 6–7

Build Applications
Chapters 8–9

Networking
Chapters 13–14

Persistence
Chapter 15

Security
Chapter 16


Kubernetes: Up and Running

Brendan Burns, Joe Beda, Kelsey Hightower & Lachlan Evenson

3rd Edition — O’Reilly Media

Level
Intermediate → Advanced

Best for
Understanding container orchestration, declarative infrastructure, scaling, self-healing and production Kubernetes workloads.

Kubernetes: Up and Running begins where Docker alone stops being enough.

Running one container is simple. Running hundreds of containers across multiple machines while keeping the desired number of replicas available, routing traffic, managing configuration, performing rolling updates and recovering from failures is a fundamentally different problem.

The book introduces Kubernetes as a declarative system: rather than manually managing individual containers, we describe the state we want and allow controllers to continuously work toward maintaining that state.

What I Use It For

  • cloud-native application principles;
  • container orchestration;
  • Kubernetes architecture;
  • Pods;
  • health checks;
  • resource requests and limits;
  • labels and selectors;
  • service discovery;
  • load balancing and Ingress;
  • ReplicaSets;
  • autoscaling;
  • Deployments and rolling updates;
  • DaemonSets and Jobs;
  • ConfigMaps and Secrets;
  • RBAC;
  • service meshes;
  • persistent storage;
  • StatefulSets;
  • security contexts;
  • Network Policies;
  • policy and governance;
  • multicluster architectures.

Chapters Worth Reading

Cloud-Native Foundations

Chapter 1 — Introduction
The architectural principles behind Kubernetes and cloud-native systems.

  • immutability;
  • declarative configuration;
  • self-healing;
  • decoupling;
  • scaling applications and teams;
  • infrastructure abstraction.

Chapter 2 — Creating and Running Containers
A bridge between container fundamentals and Kubernetes, including image building, registries, image security and container runtimes.

Kubernetes Foundations

Chapter 3 — Deploying a Kubernetes Cluster
Cluster creation, managed Kubernetes services and the main Kubernetes components.

Chapter 4 — Common kubectl Commands
Working with Kubernetes objects, namespaces, contexts and debugging commands.

Pods & Health Management

Chapter 5 — Pods
The fundamental scheduling unit in Kubernetes.

  • Pod manifests;
  • logs and command execution;
  • liveness probes;
  • readiness probes;
  • startup probes;
  • resource requests;
  • resource limits;
  • volumes.
Labels, Discovery & Networking

Chapter 6 — Labels and Annotations
Metadata and selectors used to organise and connect Kubernetes resources.

Chapter 7 — Service Discovery
Services, DNS, Cluster IPs and mechanisms for routing traffic toward changing sets of Pods.

Chapter 8 — HTTP Load Balancing with Ingress
Routing external HTTP traffic into applications running inside the cluster.

Replication, Scaling & Deployment

Chapter 9 — ReplicaSets
Reconciliation loops, desired replica counts and horizontal application scaling.

  • declarative scaling;
  • ReplicaSets;
  • autoscaling;
  • reconciliation.

Chapter 10 — Deployments
Managing application versions and updates.

  • rolling updates;
  • Recreate strategy;
  • deployment history;
  • controlled rollout;
  • rollback concepts.
Specialized Workloads

Chapter 11 — DaemonSets
Running one workload instance on selected cluster nodes.

Chapter 12 — Jobs
One-shot tasks, parallel jobs, work queues and CronJobs.

Configuration & Secrets

Chapter 13 — ConfigMaps and Secrets
Separating application configuration and sensitive information from container images.

Identity & Authorization

Chapter 14 — Role-Based Access Control for Kubernetes
Users, roles, RoleBindings and ClusterRoles used to control access to Kubernetes resources.

Service Mesh

Chapter 15 — Service Meshes
Infrastructure for managing service-to-service communication.

  • mutual TLS;
  • authentication;
  • traffic shaping;
  • observability;
  • service-mesh trade-offs.
Persistent & Stateful Workloads

Chapter 16 — Integrating Storage Solutions and Kubernetes
Persistent storage and the additional challenges introduced by stateful applications.

  • Persistent Volumes;
  • dynamic volume provisioning;
  • StatefulSets;
  • reliable singletons;
  • databases in Kubernetes.
Extending Kubernetes

Chapter 17 — Extending Kubernetes
Custom Resources and Operators used to extend the Kubernetes control model to application-specific resources.

Application Security

Chapter 19 — Securing Applications in Kubernetes
Security controls applied to containerized workloads.

  • SecurityContext;
  • Pod Security Standards;
  • service accounts;
  • RBAC;
  • RuntimeClass;
  • Network Policies;
  • image security;
  • security benchmarks.
Policy & Governance

Chapter 20 — Policy and Governance for Kubernetes Clusters
Enforcing organisational policies through admission controls and Open Policy Agent-based approaches.

Multicluster & Application Delivery

Chapter 21 — Multicluster Application Deployments
Architectural approaches for distributing applications across multiple Kubernetes clusters and regions.

Chapter 22 — Organizing Your Application
Structuring Kubernetes configuration for development, testing and production.

  • source-control organisation;
  • release progression;
  • templates;
  • Helm;
  • multi-environment deployment;
  • worldwide deployment.

My Suggested Learning Path

Cloud-Native Principles
Chapters 1–2

Kubernetes Fundamentals
Chapters 3–6

Networking & Discovery
Chapters 7–8

Scaling & Deployment
Chapters 9–12

Configuration & Access
Chapters 13–14

Service Communication & Storage
Chapters 15–16

Security & Governance
Chapters 19–20

Production Architecture
Chapters 21–22


Why I Keep Both Books

Docker Deep Dive

Container first.

  • container fundamentals;
  • runtime architecture;
  • images;
  • Dockerfiles;
  • Compose;
  • networking;
  • volumes;
  • container security.

Kubernetes: Up and Running

System first.

  • orchestration;
  • desired state;
  • scheduling;
  • replication;
  • autoscaling;
  • self-healing;
  • service discovery;
  • rolling deployment;
  • cluster security;
  • policy and governance.

Docker helps me understand the unit being deployed. Kubernetes helps me understand how thousands of those units can become a reliable system.


Topic → Book Map

Containers vs Virtual Machines

Docker Deep Dive: Chapters 1 and 7
Kubernetes: Up and Running: Chapters 1–2

Container Images & Registries

Docker Deep Dive: Chapters 6 and 8
Kubernetes: Up and Running: Chapter 2

Container Runtime

Docker Deep Dive: Chapter 5
Kubernetes: Up and Running: Chapter 2

Application Deployment

Docker Deep Dive: Chapters 8–9
Kubernetes: Up and Running: Chapters 9–10 and 22

Networking & Service Discovery

Docker Deep Dive: Chapters 13–14
Kubernetes: Up and Running: Chapters 7–8

Persistent Storage

Docker Deep Dive: Chapter 15
Kubernetes: Up and Running: Chapters 5 and 16

Scaling & Self-Healing

Docker Deep Dive: Chapters 7 and 12
Kubernetes: Up and Running: Chapters 5, 9 and 10

Security

Docker Deep Dive: Chapter 16
Kubernetes: Up and Running: Chapters 14, 19 and 20


How I Use These Books

I find container platforms easier to understand when I separate the problem into two layers: the container itself and the system responsible for managing containers at scale.

“Why does this application run consistently on my laptop and in production?”

That leads to container images, immutable artifacts, dependencies and reproducible builds.

“One application instance crashes. Who starts another one?”

That leads to restart policies at container level and reconciliation controllers, ReplicaSets and Deployments at Kubernetes level.

“Traffic suddenly triples. How can the application add capacity automatically?”

That leads to horizontal replication, autoscaling, resource requests, scheduling and load balancing.

“A container is destroyed. Why does the application data survive?”

That points toward separating ephemeral compute from persistent storage through volumes and persistent-volume abstractions.

Understand the container first. Then understand the control system that keeps thousands of containers in the state the application requires.


Related Areas

Containers and orchestration connect infrastructure with almost every other area in this library.

Operating Systems & Virtualization

Processes, kernel isolation, namespaces, resource management and virtual machines.

Software Architecture & Microservices

Independent deployment, service boundaries, progressive delivery and cloud-native applications.

Distributed Systems

Replication, scheduling, failure recovery, distributed state and coordination.

Computer Networks

Virtual networks, routing, load balancing, service discovery and network policies.

Cybersecurity & Cryptography

Image security, least privilege, identity, RBAC, secrets and network isolation.

Databases & Data Management

Persistent workloads, StatefulSets, distributed storage and database lifecycle management.


← Back to My Technical Library